Got it

Because the session has not be aging lead to new NAT do not become effective.

Latest reply: Mar 23, 2016 08:51:11 1136 1 0 0 0
The USG5000 configure NAT originally, intranet server C.C.C.C use public network address pool and address is A.A.A.A. After the change the address, reconfigure, the address pool address used by intranet server C.C.C.C change to be B.B.B.B. After the change find TCP service of C.C.C.C is broken.

Handling Process
When the service is in off-peak hour, use reset firewall session table command, clear the session table. And problem is solved.Root Cause
(1) Check the configuration, and it is correct.
(2) Use display firewall session to check session table and find C.C.C.C still use A.A.A.A address pool to access to public network session. And this session is C.C.C.C server long-term constant TCP service. So can judge that, because C.C.C.C server continued to send TCP flow, lead to TCP session cannot aging, so even if change configuration, still use the A.A.A.A address pool of session table, leading to service break.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.